Huntress MDR for Microsoft 365 Update | Huntress
ID: 2974c4d9-4cb6-5aa9-9e78-e11ac494cb32
STIX ID: report--2974c4d9-4cb6-5aa9-9e78-e11ac494cb32
Feed Name: Huntress Blog
Huntress shares a transparency update on its Managed ITDR for Microsoft 365, detailing current capabilities to detect identity-focused threats—unwanted logins, malicious inbox rules (“shadow workflows”), evasive access via Graph/API/CLI, and rogue OAuth apps—alongside lessons learned (initial gaps in geolocation/impossible-travel, detection tuning tradeoffs, and onboarding friction), recent improvements (anonymized VPN and anomalous location detections, SOC pre-filtering of alerts, streamlined onboarding), and a near-term roadmap (geo-allowlisting, TI- and location-driven detections, user behavior fingerprints, stronger inbox rule analytics, and proactive reporting).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
